Description
PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in (1) ext/soap/php_encoding.c, (2) ext/soap/php_http.c, and (3) ext/soap/soap.c, a different issue than CVE-2015-4600.
Remediation
References
Related Vulnerabilities
WordPress Plugin InstaWP Connect-1-click WP Staging & Migration Security Bypass (0.1.0.8)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5296)
Oracle Database Server CVE-2014-4300 Vulnerability (CVE-2014-4300)
Drupal Improper Access Control Vulnerability (CVE-2016-3165)